org.springframework.security:spring-security-oauth2-client
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.security:spring-security-oauth2-clientpage 1 of 1
- CVE-2021-22119HIGHCVSS 7.5EG 7.5✓ Fixed in 5.2.112021-06-29
vulnerable: 5.2.0.RELEASE ... 5.2.9.RELEASE (11 versions)
Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client…
- CVE-2022-31690HIGHCVSS 8.1EG 8.1✓ Fixed in 5.6.92022-10-31
vulnerable: 5.0.0.RELEASE ... 5.6.8 (94 versions)
Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by th…
Check whether org.springframework.security:spring-security-oauth2-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.security:spring-security-oauth2-client CVEs against the assets you own.
Start Free Scan →